Impact
A stack‑based buffer overflow exists in SKYSEA Client View and SKYMEC IT Manager. The flaw can be triggered when the affected product receives a UDP packet that is crafted to overflow an internal buffer. An attacker who has logged into a Windows system running the vulnerable product can send such a packet to another Windows system that also has the product installed and is listening for UDP traffic. Successful exploitation would allow the attacker to execute arbitrary code on the target system from the compromised source system.
Affected Systems
The vulnerable products are Sky Co., LTD.’s SKYMEC IT Manager and SKYSEA Client View, both of which run on Windows platforms. No specific version information is available in the current data, so all installed instances of these products are considered at risk.
Risk and Exploitability
The CVSS score is 5.8, indicating medium severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting it is not a high‑profile exploit. Exploitation requires an authenticated user on one host to craft and send the malicious UDP payload to a peer host, which must also host the vulnerable product and accept UDP traffic. While the attack surface is limited to networks where both systems can communicate, the potential impact of arbitrary code execution across systems warrants timely mitigation.
OpenCVE Enrichment